Also known as: APT27, LotusBlossom, APT41, Winnti, Emissary Panda, APT10, LuckyMouse, EmissaryPanda, TG-3390, Bronze Union, Lucky Mouse
Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of HyperBro malware and SysUpdate variants, with evidence of customer database and source code exfiltration. The threat actor has employed domain spoofing for command and control and has shown a consistent interest in the gambling industry. Trend Micro's analysis linked multiple tools and malware families to this campaign, indicating a sophisticated and evolving threat landscape.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Operation DRBControl is a high‑sophistication cyber‑espionage actor that uses a shared toolbox with groups such as Iron Tiger/APT27 and Winnti to conduct credential theft, data exfiltration, and ransomware delivery against government, critical infrastructure, and commercial targets in the United States, China, and Taiwan. The campaign relies on evolving backdoors (SysUpdate, HyperBro) that support both Windows and Linux, and it routinely leverages publicly known CVEs, DLL side‑loading abuses, and stolen certificates to evade defenses. While primarily focused on espionage, the group has also deployed ransomware in opportunistic attacks,
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics